CVE-2026-56021: Webmin information disclosure via regex pattern
Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a bypassable regex pattern.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
webminfrom your environment.Uninstall Webmin if it is not required on the system.
- Configuration
Enable and enforce authentication for the Webmin administrative interface to block unauthenticated access.
Webmin authentication_required = true - Compensating control
Restrict access to the Webmin management interface to trusted IP addresses or networks using firewall rules, VPN access, or network ACLs; do not expose Webmin to the public Internet.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56021?
The severity of CVE-2026-56021 is rated as medium with a score of 5.3.
How do I fix CVE-2026-56021?
To fix CVE-2026-56021, upgrade Webmin to version 2.641 or later.
What type of vulnerability is CVE-2026-56021?
CVE-2026-56021 is an information disclosure vulnerability that allows unauthorized file access.
What impact does CVE-2026-56021 have on Webmin users?
CVE-2026-56021 can allow unauthenticated attackers to read sensitive .conf files in module directories.
When was CVE-2026-56021 published?
CVE-2026-56021 was published on June 18, 2026.